The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Security Engineer / Staff Security Specialist
3-5 years in a lead roleSkills to master
- Moving from architecting individual solutions to designing broader security programmes, leading complex projects, and providing technical guidance to multiple teams. You'll need to demonstrate influence beyond your direct reports.
You're ready to move on when
- Successfully led several large-scale security projects from design to deployment.
- Consistently sought out by other teams for technical advice and problem-solving.
- Demonstrated ability to mentor and develop junior engineers effectively.
- Took initiative to identify and address systemic security issues, not just individual vulnerabilities.
- 2
Security Consultant (Big 4 or Specialist Firm)
5-8 years as a consultantSkills to master
- Broad exposure to different security challenges across various industries, strong client-facing communication, project management, and the ability to quickly assess and design security strategies for diverse environments.
You're ready to move on when
- Managed multiple client engagements, delivering impactful security solutions.
- Developed strong skills in translating technical concepts into business risks for executive audiences.
- Proven ability to build and lead project teams, often with tight deadlines.
- Deep understanding of various security frameworks and compliance requirements.
- 3
Senior Manager in IT Operations / Infrastructure
3-5 years in IT managementSkills to master
- A deep understanding of IT infrastructure, operations, and service delivery, combined with a strong security mindset. This path focuses on bringing an operational lens to security leadership, understanding the practical challenges of implementation and maintenance.
You're ready to move on when
- Successfully managed large-scale IT infrastructure or operations teams.
- Demonstrated a strong focus on security within their operational role, championing secure practices.
- Developed strong budget management and vendor relationship skills.
- Proven ability to drive process improvement and operational efficiency.